<div dir="ltr"><div>Hi,</div><div><br></div><div>Here's what the SAMLResponse I am seeing looks like (sorry for the obfuscations):</div><div><br></div><div><?xml version="1.0" encoding="UTF-8"?><saml2p:Response xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Destination="<a href="https://yyy/fed/v1/sp/sso">https://yyy/fed/v1/sp/sso</a>" ID="_d14919a3c5d9e2cc8455440f4f7443a6" InResponseTo="id-IgJu6hZAQMJmcaOUKpIS7nGx2gY-" IssueInstant="2025-04-09T13:58:19.437Z" Version="2.0"><br> <saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion"><a href="https://idp01.xxxx.com/idp/shibboleth">https://idp01.xxxx.com/idp/shibboleth</a></saml2:Issuer><br> <ds:Signature xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"><br> <ds:SignedInfo><br> <ds:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/><br> <ds:SignatureMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>"/><br> <ds:Reference URI="#_d14919a3c5d9e2cc8455440f4f7443a6"><br> <ds:Transforms><br> <ds:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/><br> <ds:Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/><br> </ds:Transforms><br> <ds:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>"/><br> <ds:DigestValue>TPt9U+iX0uSYuiSQfXEQ27fMNa9Wxyk62vD5RlRld0I=</ds:DigestValue><br> </ds:Reference><br> </ds:SignedInfo><br> <ds:SignatureValue>JTJcei7so2GAdQsv9FtOfDY7HSRZLDwj8Rc5Jt1dl4I9kvRdc3DC3AgWV8LcL5vzYyPsbjN3If56gg2YaFbahbOF/wxvyHn0LB28RZUhuH<br>.<br>.<br>+8hrh5ySlWl0ej5x0gh0doD537L1LqRZbzP0R++3BS5cqBAW8pmN1r5Tlwt0kTkHmafSOkBWvwvoZVQeDArnBLvHPtkT6Q9K2vT4QvrQjzh</ds:SignatureValue><br> <ds:KeyInfo><br> <ds:X509Data><br> <ds:X509Certificate>MIIEJzCCAo+gAwIBAgIUc33YkmOgONgZLiUdIcRsVPItWCUwDQYJKoZIhvcNAQELBQAwGjEYMBYG<br>A1UEAwwPaWRwMDEuamxmb28uY29tMB4XDTI1MDQwNjA2MjUxOFoXDTQ1MDQwNjA2MjUxOFowGjEY<br>.<br>.<br>.<br>W67RAmB9Kzs+onJfucXTYeLdTcv7sK8FPvxUWbsJj0bgXidpuhCXFUs=</ds:X509Certificate><br> </ds:X509Data><br> </ds:KeyInfo><br> </ds:Signature><br> <saml2p:Status><br> <saml2p:StatusCode Value="urn:oasis:names:tc:SAML:2.0:status:Success"/><br> </saml2p:Status><br> <saml2:Assertion xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion" ID="_bdada20483d278656a675eb121a7b8ca" IssueInstant="2025-04-09T13:58:19.437Z" Version="2.0"><br> <saml2:Issuer><a href="https://idp01.xxxx.com/idp/shibboleth">https://idp01.xxxx.com/idp/shibboleth</a></saml2:Issuer><br> <ds:Signature xmlns:ds="<a href="http://www.w3.org/2000/09/xmldsig#">http://www.w3.org/2000/09/xmldsig#</a>"><br> <ds:SignedInfo><br> <ds:CanonicalizationMethod Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/><br> <ds:SignatureMethod Algorithm="<a href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256">http://www.w3.org/2001/04/xmldsig-more#rsa-sha256</a>"/><br> <ds:Reference URI="#_bdada20483d278656a675eb121a7b8ca"><br> <ds:Transforms><br> <ds:Transform Algorithm="<a href="http://www.w3.org/2000/09/xmldsig#enveloped-signature">http://www.w3.org/2000/09/xmldsig#enveloped-signature</a>"/><br> <ds:Transform Algorithm="<a href="http://www.w3.org/2001/10/xml-exc-c14n#">http://www.w3.org/2001/10/xml-exc-c14n#</a>"/><br> </ds:Transforms><br> <ds:DigestMethod Algorithm="<a href="http://www.w3.org/2001/04/xmlenc#sha256">http://www.w3.org/2001/04/xmlenc#sha256</a>"/><br> <ds:DigestValue>asjKKk13hGvKDr6PdHdnhej/p+O1wvwJAfcK74QLsE8=</ds:DigestValue><br> </ds:Reference><br> </ds:SignedInfo><br> <ds:SignatureValue>hxBnvUgPMC2hl4b729SrvZgMDBUBIsJhYvUoF/9YiYQgKJplUieP0BjFJjnZkbrw5yw1fp0uhenTO8njZQp3ns3kWsNu992SowZWCsnHIsdZBNCAw/jQzzeq.<br>.<br>6I+IE6VG9pWez+B5GOr7fDciw8X1MzKdejQ1Y0Bq0PR//QOQV</ds:SignatureValue><br> <ds:KeyInfo><br> <ds:X509Data><br> <ds:X509Certificate>MIIEJzCCAo+gAwIBAgIUc33YkmOgONgZLiUdIcRsVPItWCUwDQYJKoZIhvcNAQELBQAwGjEYMBYG<br>A1UEAwwPaWRwMDEuamxmb28uY29tMB4XDTI1MDQwNjA2MjUxOFoXDTQ1MDQwNjA2MjUxOFowGjEY<br>.<br>.<br>.<br>FUE/+meDluNbZ1nImkA/lxDXS3/OLLkUveiJAcRhWxsNpHChdRtPVtaDqrqJYlsCpQ+WLw0H96tn<br>W67RAmB9Kzs+onJfucXTYeLdTcv7sK8FPvxUWbsJj0bgXidpuhCXFUs=</ds:X509Certificate><br> </ds:X509Data><br> </ds:KeyInfo><br> </ds:Signature><br> <saml2:Subject><br> <saml2:NameID Format="urn:oasis:names:tc:SAML:2.0:nameid-format:transient" NameQualifier="<a href="https://idp01.xxxx.com/idp/shibboleth">https://idp01.xxxx.com/idp/shibboleth</a>" SPNameQualifier="<a href="https://zzzz.com:443/fed">https://zzzz.com:443/fed</a>" xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">AAdzZWNyZXQxLCQnlD5Nbf9mkodP6zrNzVF502xO7lKRtSSsmKf5CHcGTGYT3x7F2h3uUZxQIeoigOyirgv9DQq6/b0DACc6E6JcRAaA+NX2eViJZ8O25ord14YhEoFIiDceWpaJsccotTL/jAzGp9lXbHtW7teD0oRWNZA/eiD/DUEXdH1cXP5edY1sZr++RoaxpSot4yX8hyktRALgC9rw0g==</saml2:NameID><br> <saml2:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"><br> <saml2:SubjectConfirmationData Address="100.36.177.53" InResponseTo="id-IgJu6hZAQMJmcaOUKpIS7nGx2gY-" NotOnOrAfter="2025-04-09T14:03:19.579Z" Recipient="<a href="https://yyyy/fed/v1/sp/sso">https://yyyy/fed/v1/sp/sso</a>"/><br> </saml2:SubjectConfirmation><br> </saml2:Subject><br> <saml2:Conditions NotBefore="2025-04-09T13:58:19.437Z" NotOnOrAfter="2025-04-09T14:03:19.437Z"><br> <saml2:AudienceRestriction><br> <saml2:Audience><a href="https://aaaaa.com:443/fed">https://aaaaa.com:443/fed</a></saml2:Audience><br> </saml2:AudienceRestriction><br> </saml2:Conditions><br> <saml2:AuthnStatement AuthnInstant="2025-04-09T13:58:19.350Z" SessionIndex="_dfa1ea475a6acd7db5d23318442445d8"><br> <saml2:SubjectLocality Address="100.36.177.53"/><br> <saml2:AuthnContext><br> <saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport</saml2:AuthnContextClassRef><br> </saml2:AuthnContext><br> </saml2:AuthnStatement><br> <saml2:AttributeStatement><br> <saml2:Attribute FriendlyName="schacHomeOrganization" Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"><br> <saml2:AttributeValue><a href="http://xxxx.com">xxxx.com</a></saml2:AttributeValue><br> </saml2:Attribute><br> </saml2:AttributeStatement><br> </saml2:Assertion><br></saml2p:Response><br><br></div><div><br></div><div><br></div><div><br></div></div><div id="DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br><table style="border-top:1px solid #d3d4de"><tr><td style="width:55px;padding-top:13px"><a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank"><img src="https://s-install.avcdn.net/ipm/preview/icons/icon-envelope-tick-round-orange-animated-no-repeat-v1.gif" alt="" width="46" height="29" style="width: 46px; height: 29px;"></a></td><td style="width:470px;padding-top:12px;color:#41424e;font-size:13px;font-family:Arial,Helvetica,sans-serif;line-height:18px">Virus-free.<a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank" style="color:#4453ea">www.avast.com</a></td></tr></table><a href="#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2" width="1" height="1"></a></div><br><div class="gmail_quote gmail_quote_container"><div dir="ltr" class="gmail_attr">On Wed, Apr 9, 2025 at 11:09 AM o haya <<a href="mailto:ohaya1001@gmail.com">ohaya1001@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div>Hi Scott and Peter!!</div><div><br></div><div>I really appreciate your responses/comments, especially Scott's comments about the attribute resolver... it is a LOT of information, especially conceptually, to digest for a newbie and the "glue" to the different pieces of information is the hardest part to try to understand. I mean I feel like I have a LOT of experience with federation, LDAPs, etc., but most of my work has been with COTS products, and some of the concepts in Shibboleth are still a little new to me, so it is taking a while for me. <br></div><div><br></div><div>I think that I am kind of a "learn by doing" type person, so, personally, it is important in my learning process to get something, even something simple, working, and then I can go from there, so that is currently what I am trying to get to/achieve. Even if I can get just one of 2 attributes and mainly, the nameid part working, that would be a great starting point.</div><div><br></div><div>As far as specifics, as mentioned, I am using OpenDJ (I tend to use OpenDJ in development, because it includes a control panel for administration, plus a standalone LDAP instance, in one package, but I have used Oracle OUD, AD, and even the old Oracle OID and the original SunDS, for years). OpenDJ includes a standard LDAP schema, similar to SunDS, I think, and currently I've configured the BEGINNING part of the Shib ldap properties:</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">==================================================================================</blockquote><blockquote># LDAP authentication (and possibly attribute resolver) configuration<br># Note, this doesn't apply to the use of JAAS authentication via LDAP<br><br>## Authenticator strategy, either anonSearchAuthenticator, bindSearchAuthenticator, directAuthenticator, adAuthenticator<br>idp.authn.LDAP.authenticator = anonSearchAuthenticator<br><br>## Connection properties ##<br>idp.authn.LDAP.ldapURL = ldap://localhost:1389<br>idp.authn.LDAP.useStartTLS = false<br># Time to wait for startTLS responses<br>#idp.authn.LDAP.startTLSTimeout = PT3S<br># Time to wait for connections to open<br>#idp.authn.LDAP.connectTimeout = PT3S<br># Time to wait for operation responses (e.g. search, bind)<br>#idp.authn.LDAP.responseTimeout = PT3S<br># Connection strategy to use when multiple URLs are supplied, either ACTIVE_PASSIVE, ROUND_ROBIN, RANDOM<br>#idp.authn.LDAP.connectionStrategy = ACTIVE_PASSIVE<br><br>## SSL configuration, either jvmTrust, certificateTrust, or keyStoreTrust<br>#idp.authn.LDAP.sslConfig = certificateTrust<br>## If using certificateTrust above, set to the trusted certificate's path<br>#idp.authn.LDAP.trustCertificates = %{idp.home}/credentials/ldap-server.crt<br>## If using keyStoreTrust above, set to the truststore path<br>#idp.authn.LDAP.trustStore = %{idp.home}/credentials/ldap-server.truststore<br><br>## Return attributes during authentication<br># Setting this property will cause entry resolution to occur as part of authentication<br># Note that this property is not compatible with the adAuthenticator<br>#idp.authn.LDAP.returnAttributes = passwordExpirationTime,loginGraceRemaining<br><br>## DN resolution properties ##<br><br># Search DN resolution, used by anonSearchAuthenticator, bindSearchAuthenticator<br># for AD: CN=Users,DC=example,DC=org<br>idp.authn.LDAP.baseDN = ou=people,dc=xxxx,dc=com<br>idp.authn.LDAP.subtreeSearch = true<br>idp.authn.LDAP.userFilter = (cn={user})<br># bind search configuration<br># for AD: idp.authn.LDAP.bindDN=<a href="mailto:adminuser@domain.com" target="_blank">adminuser@domain.com</a><br>idp.authn.LDAP.bindDN = cn=directory manager<br><br># Format DN resolution, used by directAuthenticator, adAuthenticator<br># for AD use idp.authn.LDAP.dnFormat=%<a href="mailto:s@domain.com" target="_blank">s@domain.com</a><br>idp.authn.LDAP.dnFormat = cn=%s,ou=people,dc=xxxx,dc=com<br></blockquote><blockquote>===========================================================================</blockquote><div><br></div><div><br></div><div>I have not changed anything in saml-nameid.xml or attribute-resolver.xml (I did make changes which caused the IdP to fail to start earlier, but I've since restored them to original).</div><div><br></div><div>Jim</div><div><br></div><div><br></div></div><div id="m_-3722657078113250533DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2"><br><table style="border-top:1px solid rgb(211,212,222)"><tbody><tr><td style="width:55px;padding-top:13px"><a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" target="_blank"><img src="https://s-install.avcdn.net/ipm/preview/icons/icon-envelope-tick-round-orange-animated-no-repeat-v1.gif" alt="" width="46" height="29" style="width: 46px; height: 29px;"></a></td><td style="width:470px;padding-top:12px;color:rgb(65,66,78);font-size:13px;font-family:Arial,Helvetica,sans-serif;line-height:18px">Virus-free.<a href="https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=webmail" style="color:rgb(68,83,234)" target="_blank">www.avast.com</a></td></tr></tbody></table><a href="#m_-3722657078113250533_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2" width="1" height="1"></a></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Wed, Apr 9, 2025 at 8:37 AM Cantor, Scott via users <<a href="mailto:users@shibboleth.net" target="_blank">users@shibboleth.net</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">> I was seeing errors in the idp-warn.log about missing > <br>
> certificat (.crt) files, even though I have TLS set to 'false' in <br>
> the ldap.properties file.<br>
<br>
That's doesn't mean you're not applying other settings that assume they exist.<br>
<br>
But using ldap:// instead of ldaps:// with the startTLS setting off should not result in actual use of TLS in either of the two ways it gets used. jvmTrust is probably a reasonable fallback option to set when not using TLS at all since it shouldn't matter and doesn't require additional setup.<br>
<br>
As for the documentation, I don't think the resolver material is approachable, it doesn't explain any concepts. A section outlining what it's really doing and how the connectors and definitions get applied is needed.<br>
<br>
Having said which, the LDAP data connector topic should be all anybody needs to set up a query, not to mention there's a specific example file in the install for LDAP.<br>
<br>
But as for the NameID generation matetrial: that is as good as it's ever going to get IMHO.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>
</blockquote></div>